CVE-2023-31416: Elastic Cloud on Kubernetes (ECK) secret token configuration issue
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-31416.
What is the title of the vulnerability?
The title of the vulnerability is Elastic Cloud on Kubernetes (ECK) secret token configuration issue.
What is the description of the vulnerability?
The secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0, which could lead to anonymous requests being accepted and data ingested into the APM deployment.
What is the affected software?
The affected software includes Elastic Cloud on Kubernetes (ECK) version up to exclusive 2.8 and APM Server version from inclusive 8.0.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 5.3.
How can I fix the vulnerability?
To fix the vulnerability, update ECK to version 2.8 or higher, and update APM Server to a version lower than 8.0.